Get in Touch
 Duration 21 hours

Course Outline

1. The Scope and Concepts of Static Code Analysis

  • Definitions: static analysis, SAST, rule categories, and severity levels
  • The role of static analysis in a secure SDLC and risk coverage
  • How SonarQube aligns with security controls and developer workflows

2. SonarQube Overview: Architecture and Features

  • Essential services, database, and scanner components
  • Best practices for Quality Gates, Quality Profiles, and gate configurations
  • Security-focused features: vulnerabilities, SAST rules, and CWE mapping

3. Navigating the SonarQube Server Interface

  • Tour of the server UI: projects, issues, rules, metrics, and governance views
  • Analyzing issue pages, traceability, and remediation advice
  • Generating and exporting reports

4. Configuring SonarScanner with Build Tools

  • Setting up SonarScanner for Maven, Gradle, Ant, and MSBuild
  • Best practices for scanner properties, exclusions, and multi-module projects
  • Creating necessary test data and coverage reports for precise analysis

5. Azure DevOps Integration

  • Establishing SonarQube service connections in Azure DevOps
  • Including SonarQube tasks in Azure Pipelines and adding PR decorations
  • Importing Azure Repos into SonarQube to automate analyses

6. Project Configuration and Third-Party Analyzers

  • Setting project-level Quality Profiles and selecting rules for Java and Angular
  • Utilizing third-party analyzers and managing the plugin lifecycle
  • Defining analysis parameters and understanding parameter inheritance

7. Roles, Responsibilities, and Secure Development Methodology Review

  • Role separation: developers, reviewers, DevOps, and security owners
  • Creating a roles and responsibilities matrix for CI/CD processes
  • Reviewing and recommending improvements to existing secure development methodologies

8. Advanced Topics: Adding Rules, Tuning, and Enhancing Global Security

  • Using the SonarQube Web API to create and manage custom rules
  • Modifying Quality Gates and enforcing automated policies
  • Strengthening SonarQube server security and access control practices

9. Hands-on Lab Sessions (Practical Application)

  • Lab A: Set up SonarScanner for five Java repositories (using Quarkus where relevant) and review results
  • Lab B: Configure Sonar analysis for one Angular front-end and interpret findings
  • Lab C: Comprehensive pipeline lab—integrate SonarQube with an Azure DevOps pipeline and enable PR decoration

10. Testing, Troubleshooting, and Report Interpretation

  • Strategies for generating test data and measuring coverage
  • Addressing common scanner, pipeline, and permission issues
  • Presenting SonarQube reports to both technical and non-technical stakeholders

11. Best Practices and Recommendations

  • Selecting rule sets and strategies for incremental enforcement
  • Workflow suggestions for developers, reviewers, and build pipelines
  • A roadmap for scaling SonarQube in enterprise settings

Summary and Next Steps

Requirements

  • Knowledge of the software development lifecycle
  • Experience with source control and fundamental CI/CD concepts
  • Familiarity with Java or Angular development environments

Target Audience

  • Developers (Java / Quarkus / Angular)
  • DevOps and CI/CD engineers
  • Security engineers and application security reviewers

Number of participants


Price per participant

Testimonials (1)

Upcoming Courses

Related Categories